Enterprise intranet information security solution supporting multiple encryption protection
By using multi-factor authentication and end-to-end tunneling technology, the shortcomings of traditional VPNs and carrier leased lines in terms of security and flexibility are solved, enabling high-security, low-latency mobile office access within the enterprise intranet and simplifying operation and maintenance management.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- SHENZHEN XINXUE TECHNOLOGY CO LTD
- Filing Date
- 2026-01-28
- Publication Date
- 2026-04-24
AI Technical Summary
Traditional enterprise intranet access solutions are inadequate in terms of security, flexibility, and user experience. VPNs are vulnerable to network attacks, have lax access control, and are difficult to adapt to the needs of mobile offices. Dedicated lines from carriers are fixed and difficult to adapt to mobile office scenarios.
By employing a multi-factor fusion authentication module combined with a portable encrypted gateway and carrier network infrastructure, and through biometrics, dynamic token authentication, and hardware-level security protection, an end-to-end secure data tunnel is established. Fine-grained permissions are dynamically calculated and monitored in real time, achieving highly secure and flexible mobile office access.
It enhances the stability and flexibility of secure access to enterprise intranets, solves the problems of easy cracking of single authentication and VPN traffic congestion in traditional VPNs, achieves a highly secure and low-latency mobile office experience, and simplifies operation and maintenance through dynamic permission management.
Smart Images

Figure CN121923914A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the technical field of computer network information security, specifically to a solution for enterprise intranet information security that supports multiple encryption protections. Background Technology
[0002] With the accelerated advancement of enterprise informatization and digital transformation, especially with the increasing demands for intranet information security, secure access in remote and mobile office scenarios has become a key requirement. Traditional intranet access solutions mainly include two types: Virtual Private Network (VPN) and leased line access. Although both can meet basic remote access needs to a certain extent, they still have significant shortcomings in terms of security, flexibility, and user experience.
[0003] Traditional VPN solutions enable remote users to access the corporate intranet by establishing encrypted tunnels over the public internet. Users authenticate using an account and password to access the intranet. Although VPN technology is relatively mature and flexible in deployment, it has significant inherent drawbacks: the VPN gateway's IP address and port are constantly exposed to the public internet, making it vulnerable to network attacks and scanning; its reliance on a single account and password authentication mechanism results in relatively crude access control, and credential leakage can threaten the entire intranet; all remote access traffic must be aggregated and forwarded through a central gateway, which can easily lead to bandwidth congestion, increased latency, and a degraded user experience when there is a large volume of concurrent access; there is poor compatibility between VPN devices from different vendors, making troubleshooting difficult when using mixed networks; adding access nodes or users is cumbersome and difficult to adapt to the dynamic expansion needs of enterprises; while carrier-dedicated line access technology can provide stable, reliable, and highly secure connections, the access point is fixed, making it difficult to adapt to mobile office scenarios. Summary of the Invention
[0004] The purpose of this invention is to provide a solution for enterprise intranet information security that supports multiple encryption protections, so as to solve the problems mentioned in the background art.
[0005] To achieve the above objectives, the present invention provides the following technical solution: a solution for enterprise intranet information security supporting multiple encryption protections. This method is based on system implementation, and the system includes user terminals, a portable encryption gateway, carrier network infrastructure, and an enterprise intranet. The method includes the following steps: S1: The user terminal initiates an access request to the mobile encrypted gateway, triggering the multi-factor authentication module within the mobile encrypted gateway to start the identity verification process; S2: The multi-factor fusion authentication module collects the user's first type of biometric data and performs a first-level matching verification with the baseline template pre-installed in the gateway's secure storage area; if the matching is successful, a first authentication token is generated and the second type of dynamic challenge response verification is activated. S3: Dynamic challenge response verification is based on timestamp t and gateway unique device identifier DID. A one-time challenge code C1 is generated through the first algorithm function and sent to the cloud authentication server. The user needs to respond through the bound second authentication device to generate response code R1. S4: The mobile encrypted gateway verifies the validity of the response code R1 through the second algorithm function. If the verification is successful, it generates an encrypted authentication data packet P_auth containing the gateway IMEI, fingerprint module ID, SIM card iccid information and session key Seed, and sends it to the cloud authentication management platform through the mobile network. S5: The cloud-based authentication management platform decrypts and parses the data packet P_auth, compares it with the gateway device information pre-set on the platform for authentication; after successful authentication, it calls the SIM card management and policy control platform interface in the operator's network infrastructure to forward the authentication success command and related session data; S6: The SIM card management and policy control platform calculates the dynamic network access permission set Perm of the session through a third algorithm function based on the received instructions and session data. The permission set includes at least the accessible intranet IP address range, port number list and application protocol type. S7: The platform generates a real-time authorization command for the SIM card built into the mobile encrypted gateway based on the dynamic network access permission set Perm. The real-time authorization command is sent through the operator's dedicated line control channel, which enables the SIM card to logically access a secure data tunnel pointing to the designated enterprise intranet. The secure data tunnel is isolated from the public Internet. S8: After authorization, all user terminal data streams forwarded by the portable encrypted gateway are transmitted through a secure data tunnel, directly reaching the enterprise intranet boundary for security. S9: The enterprise intranet boundary security device receives traffic from the secure data tunnel. Based on the session key Seed and dynamic network access permission set Perm synchronized by the cloud authentication management platform, it decrypts the traffic and performs fine-grained access control checks before forwarding the legitimate traffic to the target intranet resources.
[0006] Preferably, the first algorithm function f1 is a one-way hash function used to generate a one-time challenge code C1, and its specific expression is as follows:
[0007] Where K_shared is the pre-shared key, || represents the concatenation operation, and the validity period Δt of the challenge code C1 is configured by the policy.
[0008] Preferably, the implementation process of the third algorithm function Φ, used to calculate the dynamic network access permission set Perm, includes the following steps: S31: Query the basic permission matrix B based on the UID to obtain the user's static permission vector P_static; S32: Query the device trust level table based on DID to obtain the device weight coefficient ω; S33: Use the session key Seed as a random number seed to generate a dynamic adjustment factor δ that is related to the environmental context; S34: Calculate the final dynamic network access permission set, its expression is:
[0009] Where P_max is the maximum possible set of permissions, ∩ represents the intersection operation of sets, and the coefficients are normalized after adjustment.
[0010] Preferably, the portable encrypted gateway includes a main communication module, a hardware security chip, and a biometric collector; The multi-factor fusion authentication module runs in the protected execution environment of the hardware security chip. The storage and matching operation of the reference template of the first type of biometric data are completed in the protected execution environment, and the matching result is output to the main communication module in the form of a security tag.
[0011] Preferably, the generation of the encrypted authentication data packet P_auth adopts a hybrid encryption method. First, a symmetric encryption algorithm is used to encrypt the core authentication data with the session key Seed. Then, the public key of the cloud authentication management platform is used to perform asymmetric encryption on the session key Seed and the data digest to form the final data packet.
[0012] Preferably, the establishment of the secure data tunnel adopts hard pipe isolation based on MPLS-VPN technology on the operator network side, and assigns a private mobile IP address within the operator network to the SIM card. The private mobile IP address and the enterprise intranet address space are mapped and routed through the tunnel boundary gateway.
[0013] Preferably, the mobile encryption gateway implements a differentiated encryption strategy based on application type for the forwarded data stream. For data streams with a confidentiality level higher than the threshold θ, end-to-end additional encryption is performed using the national cryptographic SM4 algorithm; for ordinary office data streams, basic encryption relies on a secure data tunnel.
[0014] Preferably, the method also includes security monitoring and dynamic access control. The cloud authentication management platform and the SIM card management and policy control platform work together to monitor the traffic patterns, session activity and abnormal behavior indicators of the secure data tunnel in real time. When the abnormal behavior indicators exceed the preset threshold, the platform recalculates and issues a reduced set of dynamic network access permissions through the fourth algorithm function, immediately revokes the authorization, disconnects the tunnel connection, and sends the alarm information to the enterprise security management center.
[0015] Preferably, the fourth algorithm function is a permission decay function based on risk score R, used to calculate the reduced permission set, and its expression is:
[0016] Where λ is the attenuation coefficient, and the risk score R is calculated by weighting multiple monitoring indicators.
[0017] Preferably, this method is based on system implementation, and the system specifically includes: A portable encryption gateway is used to perform multi-factor authentication of user identity, generate encrypted authentication data packets, and send and receive data streams encrypted via a secure data tunnel through a built-in SIM card. The cloud-based authentication management platform is used to receive and verify authentication data reported by the gateway, and to call the operator's platform interface to coordinate tunnel authorization and permission management. Operator network infrastructure, including the radio access network and core network that provide mobile access, as well as the SIM card management and policy control platform responsible for SIM card lifecycle management, policy control and secure tunnel establishment; The enterprise intranet boundary security device is configured to interface with the secure tunnel endpoint of the operator's network infrastructure and is responsible for performing final decryption, access control and auditing of inbound and outbound tunnel traffic based on dynamic permissions.
[0018] Compared with the prior art, the beneficial effects of the present invention are: This invention achieves a breakthrough in enterprise intranet security by integrating a portable encrypted gateway, multi-factor authentication, and carrier-grade secure dedicated tunnels. First, it employs biometric and dynamic token dual-factor authentication, along with hardware-level security protection, completely resolving the risks of traditional VPN authentication methods being singular and vulnerable to brute-force attacks. Second, it utilizes carrier-grade MPLS-VPN and other hard-pipe technologies to establish end-to-end dedicated tunnels, enabling mobile access to combine the stability, low latency, and high security of dedicated lines, avoiding congestion and exposure on the public network. Third, by dynamically calculating fine-grained permissions and monitoring and adjusting permissions in real time, it achieves precise matching of permissions according to the scenario and automatic response to abnormal behavior, greatly simplifying operation and maintenance management. The overall solution perfectly supports the flexible needs of mobile office while ensuring high security. Attached Figure Description
[0019] Figure 1 This invention provides an overall access flowchart for an enterprise intranet information security solution system that supports multiple encryption protection.
[0020] Figure 2 This is a flowchart of the two-factor authentication process of the present invention.
[0021] Figure 3 This is a flowchart of the dynamic monitoring and permission adjustment process of this invention. Detailed Implementation
[0022] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0023] Please see Figure 1 This invention provides a technical solution: This embodiment provides a solution for enterprise intranet information security that supports multiple encryption protections. The system on which this embodiment is based includes user terminals, such as laptops, portable encryption gateways, such as 5G mobile routers with integrated biometric and security chips, cloud authentication management platforms, operator network infrastructure, including wireless access networks, core networks, dedicated SIM card management and policy control platforms, and enterprise intranets. Security gateway devices are deployed at the boundaries of the enterprise intranets.
[0024] The method includes the following steps: S1: The user terminal initiates an access request to the mobile encrypted gateway, triggering the multi-factor authentication module within the mobile encrypted gateway to start the identity verification process; This step changes the access point from the traditional public IP address and port to a mobile device that requires physical contact and triggers local authentication. This fundamentally avoids the long-term exposure of the VPN gateway service port on the public network, eliminates the initial risk point of remote scanning and attack, and shrinks the network attack surface from the unlimited public network to a single device that requires physical proximity, greatly improving the security of the initial access process.
[0025] S2: The multi-factor authentication module drives the integrated biometric data collector, such as a fingerprint sensor, to collect the user's first-level biometric data. The multi-factor authentication module runs on the gateway's built-in hardware security chip, such as the SE's protected execution environment. The collected feature data is sent to this environment and undergoes a first-level matching verification with a baseline template pre-installed in the gateway's secure storage area. If the match is successful, an immutable first authentication token is generated within the security chip, activating the second-level dynamic challenge-response verification, such as... Figure 2 As shown; By leveraging the isolated execution and secure storage capabilities provided by the hardware security chip, it ensures that biometric templates and the matching process are not stolen or tampered with by malicious software on the host system. Matching is completed locally without the need to transmit original biometric information, protecting user privacy and providing high-strength authentication, replacing weak password methods and effectively preventing unauthorized access due to password leakage. Localized processing also avoids performance bottlenecks and single points of failure risks on the authentication server.
[0026] S3: Dynamic challenge-response verification is based on timestamp t and gateway unique device identifier DID. A one-time challenge code C1 is generated through the first algorithm function and sent to the cloud authentication management platform. The user needs to respond through the bound second authentication device to generate a response code R1. After successful biometric verification, dynamic challenge-response verification is activated. This verification, based on the current timestamp t and the gateway's unique device identifier DID, generates a one-time challenge code C1 using the first algorithm function f1. The first algorithm function f1 is a one-way hash function used to generate the one-time challenge code C1, and its specific expression is as follows:
[0027] Where K_shared is the pre-shared key pre-installed in the gateway and security chip, || represents the string concatenation operation, and the generated C1 is sent to the user's bound second authentication device, such as a mobile phone, through the local connection. The user needs to use the second authentication device within the specified validity period Δt. Usually, an authentication APP is installed to view C1 and respond, generating a response code R1.
[0028] By introducing a time factor t and a device factor DID, each generated challenge code C1 is unique and time-limited. Even if an attacker intercepts a communication, it cannot be reused. The second authentication device, the mobile phone, is used as an independent factor to verify the second credential, forming a two-factor authentication system of biometrics and dynamic tokens. This greatly increases the difficulty of brute-force and replay attacks. Even if biometric data is forged in extreme cases, attackers still cannot obtain a real-time dynamic token, thus enhancing security.
[0029] S4: The mobile encrypted gateway verifies the validity of the response code R1 returned by the user through the second algorithm function. The second algorithm function and the second authentication device agree on the verification algorithm, such as the same HMAC calculation. After both factors are verified, the gateway's authentication module is considered to be successfully completed. At this time, the gateway generates an encrypted authentication data packet P_auth containing the gateway device's International Mobile Equipment Identity (IMEI), fingerprint module ID, integrated circuit card identification code (ICCID) of the built-in SIM card, and a randomly generated session key Seed.
[0030] The generation of P_auth employs a hybrid encryption method. First, a symmetric encryption algorithm, such as AES-256, is used to encrypt the core hardware identification data—IMEI, fingerprint module ID, and ICCID—using the Seed as the key. Then, the public key of the operator's SIM card management and policy control platform is used to perform asymmetric encryption on the Seed and the digest of the aforementioned core data, such as RSA-OAEP. The final P_auth is then sent to the cloud authentication management platform via the gateway's mobile network module and the built-in SIM card. Figure 3 As shown.
[0031] All user-side factors are verified locally, and only the verification results and necessary identification information are uploaded after high-strength encryption. The use of session keys (Seed) ensures the session independence of each authentication communication. A set of immutable hardware unique identifiers (IMEI, fingerprint module ID, ICCID) replaces the relatively soft user account and general device identifier, achieving strong binding authentication for legitimate device hardware combinations. The core authentication logic is pushed down to edge devices, and the platform only acts as a policy execution and tunnel management node, reducing the pressure on the centralized authentication server, improving the overall scalability and anti-DDoS attack capability of the system, and ensuring signaling security through encrypted transmission.
[0032] S5: After receiving P_auth, the cloud authentication management platform decrypts it using its own private key to obtain the session key Seed. Then, it decrypts the Seed to obtain core hardware identifiers such as IMEI, fingerprint module ID, and ICCID. The platform compares the above information with the pre-set device whitelist and the user-device binding relationship for authentication. After successful verification, the platform generates an authentication success command and calls the operator's SIM card management and policy control platform through a secure interface. The platform forwards the session key Seed and related device identifiers to the operator platform, triggering the subsequent tunnel establishment process.
[0033] S6: After receiving instructions and data from the cloud authentication management platform, the operator's SIM card management and policy control platform first verifies whether the IMEI, ICCID, and the binding relationship between the legitimate device and card number recorded by the platform are consistent. After successful verification, the platform dynamically calculates the precise permission set Perm for this session based on the preset policy and the third algorithm function Φ. The calculation process is as follows: S61: Query the basic permission matrix B based on the UID to obtain the user's static job permission vector P_static, for example, allowing access to the financial server IP segment.
[0034] S62: Query the device trust level table based on DID to obtain the weight coefficient ω of the specific gateway device. For example, the company-issued device has ω=1.0, and the personal registered device has ω=0.6.
[0035] S63: Using the unique Seed of this session as the random number seed, combined with the current environmental context, such as whether the access time is a weekday and whether the GPS location is in a frequently used location, a dynamic adjustment factor δ is generated, with a range of, for example, 0.8-1.2.
[0036] S64: Calculate the final dynamic network access permission set:
[0037] Here, P_max represents the theoretically maximum set of permissions that a user can be granted. ∩ represents the intersection operation, which is to take the intersection of P_static and the coefficient-adjusted P_max, and then normalize the result to ensure the validity of permissions. Permission calculation integrates user identity, device trustworthiness, and real-time environmental context to achieve refined and scenario-based dynamic management of permissions. The introduction of Seed makes the δ factor unpredictable, increases the random security of permission allocation, and realizes the dynamic implementation of the principle of least privilege. Even if account and device information is leaked, attackers may obtain completely different permissions by using the same device to initiate sessions at different times and locations, which greatly limits the scope of lateral movement attacks and solves the problem of the traditional VPN's coarse permission management.
[0038] S7: After the platform calculates Perm, it generates a real-time authorization command for the specific SIM card. This command is sent to the core network element through a secure dedicated control channel within the operator's network, such as the Diameter protocol. After the command takes effect, the mobile data traffic of the SIM card is guided to a secure data tunnel built on MPLS-VPN technology on the operator's network side. This tunnel is logically connected to the operator's leased dedicated line, such as the SD-WAN dedicated line, forming an end-to-end secure data tunnel from the mobile cellular network directly to the boundary of the enterprise's intranet. At the same time, a private IP address is assigned to the SIM card in the operator's mobile intranet for routing within the tunnel.
[0039] Leveraging the network virtualization capabilities of telecom operators, an isolated logical channel is established between the mobile access network and the fixed leased line network. Data flow never enters the public internet, fundamentally solving the congestion, latency, and exposure risks associated with traditional VPN traffic traversing the public internet. This achieves a stable, low-latency, and highly secure transmission experience comparable to fixed leased lines, while retaining the flexibility of mobile access. It perfectly combines the security and stability of leased lines with the convenience of mobile access.
[0040] S8: After the mobile encrypted gateway receives confirmation of successful tunnel establishment, all user terminal internet traffic is forwarded by the gateway through the established secure data tunnel. For traffic, the gateway implements a differentiated encryption strategy: it identifies the application type through deep packet inspection, and for data streams marked as having a confidentiality level higher than the preset threshold θ, it uses the national cryptographic SM4 algorithm for end-to-end encryption in addition to tunnel encryption; ordinary office traffic relies only on the tunnel itself for encryption, and the traffic goes directly to the enterprise intranet boundary security device. S9: The border device holds the session key Seed and permission set Perm synchronized with the cloud authentication management platform. First, it decrypts the tunnel encryption. For traffic that requires end-to-end encryption, it decrypts it using the key derived from Seed. Then, based on the detailed IP, port, and protocol rules in Perm, it performs fine-grained access control checks on the decrypted traffic, allowing only traffic that conforms to the Perm rules to the target resources on the internal network.
[0041] At the transport layer, namely tunnel encryption, and at the application layer, namely end-to-end encryption, dual encryption protection is provided. Differentiated security strategies are implemented based on data sensitivity. Boundary security devices perform access control based on dynamically issued precise permissions, achieving high-strength encryption and on-demand encryption throughout the data transmission process, meeting the protection requirements of data with different security levels. Based on dynamic permission-based boundary control, in-depth defense from the network layer to the application layer is achieved.
[0042] As a preferred extension of this embodiment, the cloud authentication management platform collaborates with the SIM card management and policy control platform. The SIM card management and policy control platform continuously monitors the traffic patterns, session activity, and abnormal behavior indicators of each secure data tunnel in real time, such as high-frequency access outside of working hours or access to infrequently used resources. When the comprehensive score R of abnormal behavior exceeds a preset threshold, the platform automatically calls the fourth algorithm function to dynamically decay the current permission set. The function expression is:
[0043] Where λ is the attenuation coefficient configured by the system. The calculated reduced permission set is immediately issued, and may even directly trigger authorization revocation and tunnel disconnection. Real-time alarms are sent to the enterprise security management center, where continuous behavioral analysis is used for dynamic risk assessment. Based on the assessment results, permissions are automatically adjusted or connections are cut off, realizing the evolution of security capabilities from static defense to dynamic perception and proactive response. It can automatically take restrictive measures before potential threats cause actual losses, greatly improving the system's adaptive protection capabilities against internal anomalies and new attacks.
[0044] Although embodiments of the invention have been shown and described, it will be understood by those skilled in the art that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the appended claims and their equivalents.
Claims
1. A solution for enterprise intranet information security that supports multiple encryption protections, characterized in that: This method is based on system implementation, which includes user terminals, portable encrypted gateways, cloud-based authentication management platforms, carrier network infrastructure, and enterprise intranets. The method includes the following steps: S1: The user terminal initiates an access request to the mobile encrypted gateway, triggering the multi-factor authentication module within the mobile encrypted gateway to start the identity verification process; S2: The multi-factor fusion authentication module collects the user's first type of biometric data and performs a first-level matching verification with the baseline template pre-installed in the gateway's secure storage area; if the matching is successful, a first authentication token is generated and the second type of dynamic challenge response verification is activated. S3: Dynamic challenge-response verification is based on timestamp t and gateway unique device identifier DID. A one-time challenge code C1 is generated through the first algorithm function and sent to the cloud authentication management platform. The user needs to respond through the bound second authentication device to generate a response code R1. S4: The mobile encrypted gateway verifies the validity of the response code R1 through the second algorithm function. If the verification is successful, it generates an encrypted authentication data packet P_auth containing the gateway IMEI, fingerprint module ID, SIM card iccid information and session key Seed, and sends it to the cloud authentication management platform through the mobile network. S5: The cloud-based authentication management platform decrypts and parses the data packet P_auth, compares it with the gateway device information pre-set on the platform for authentication; after successful authentication, it calls the SIM card management and policy control platform interface in the operator's network infrastructure to forward the authentication success command and related session data; S6: The SIM card management and policy control platform calculates the dynamic network access permission set Perm of the session through a third algorithm function based on the received instructions and session data. The permission set includes at least the accessible intranet IP address range, port number list and application protocol type. S7: The platform generates a real-time authorization command for the SIM card built into the mobile encrypted gateway based on the dynamic network access permission set Perm. The real-time authorization command is sent through the operator's dedicated line control channel, which enables the SIM card to logically access a secure data tunnel pointing to the designated enterprise intranet. The secure data tunnel is isolated from the public Internet. S8: After authorization, all user terminal data streams forwarded by the portable encrypted gateway are transmitted through a secure data tunnel, directly reaching the enterprise intranet boundary for security. S9: The enterprise intranet boundary security device receives traffic from the secure data tunnel. Based on the session key Seed and dynamic network access permission set Perm synchronized by the cloud authentication management platform, it decrypts the traffic and performs fine-grained access control checks before forwarding the legitimate traffic to the target intranet resources.
2. The enterprise intranet information security solution supporting multiple encryption protection as described in claim 1, characterized in that: The first algorithm function f1 is a one-way hash function used to generate a one-time challenge code C1, and its specific expression is as follows: Where K_shared is the pre-shared key, || represents the concatenation operation, and the validity period Δt of the challenge code C1 is configured by the policy.
3. The enterprise intranet information security solution supporting multiple encryption protection as described in claim 1, characterized in that: The implementation of the third algorithm function Φ is used to calculate the dynamic network access permission set Perm, and includes the following steps: S31: Query the basic permission matrix B based on the UID to obtain the user's static permission vector P_static; S32: Query the device trust level table based on DID to obtain the device weight coefficient ω; S33: Use the session key Seed as a random number seed to generate a dynamic adjustment factor δ that is related to the environmental context; S34: Calculate the final dynamic network access permission set, its expression is: Where P_max is the maximum possible set of permissions, ∩ represents the intersection operation of sets, and the coefficients are normalized after adjustment.
4. The enterprise intranet information security solution supporting multiple encryption protection as described in claim 1, characterized in that: The portable encryption gateway includes a main communication module, a hardware security chip, and a biometric collector. The multi-factor fusion authentication module runs in the protected execution environment of the hardware security chip. The storage and matching operation of the reference template of the first type of biometric data are completed in the protected execution environment, and the matching result is output to the main communication module in the form of a security tag.
5. A solution for enterprise intranet information security supporting multiple encryption protection as described in claim 1, characterized in that: The encrypted authentication data packet P_auth is generated using a hybrid encryption method. First, a symmetric encryption algorithm is used to encrypt the core authentication data with the session key Seed. Then, the public key of the cloud authentication management platform is used to perform asymmetric encryption on the session key Seed and the data digest to form the final data packet.
6. A solution for enterprise intranet information security supporting multiple encryption protection as described in claim 1, characterized in that: The establishment of the secure data tunnel employs hard-pipe isolation based on MPLS-VPN technology on the operator network side, and assigns a private mobile IP address within the operator network to the SIM card. The private mobile IP address and the enterprise intranet address space are mapped and routed through the tunnel boundary gateway.
7. A solution for enterprise intranet information security supporting multiple encryption protection as described in claim 1, characterized in that: The mobile encryption gateway implements differentiated encryption strategies based on application type for forwarded data streams. For data streams with a confidentiality level higher than the threshold θ, end-to-end additional encryption is performed using the national cryptographic SM4 algorithm; for ordinary office data streams, basic encryption relies on the secure data tunnel.
8. A solution for enterprise intranet information security supporting multiple encryption protection as described in claim 1, characterized in that: The method also includes security monitoring and dynamic access control. The cloud authentication management platform and the SIM card management and policy control platform work together to monitor the traffic patterns, session activity and abnormal behavior indicators of the secure data tunnel in real time. When the abnormal behavior indicators exceed the preset threshold, the platform recalculates and issues a reduced set of dynamic network access permissions through the fourth algorithm function, immediately revokes the authorization, disconnects the tunnel connection, and sends the alarm information to the enterprise security management center.
9. A solution for enterprise intranet information security supporting multiple encryption protection as described in claim 8, characterized in that: The fourth algorithm function is a permission decay function based on risk score R, used to calculate the reduced permission set, and its expression is: Where λ is the attenuation coefficient, and the risk score R is calculated by weighting multiple monitoring indicators.
10. A solution for enterprise intranet information security supporting multiple encryption protection as described in claim 1, characterized in that: This method is based on system implementation, and the system specifically includes: A portable encryption gateway is used to perform multi-factor authentication of user identity, generate encrypted authentication data packets, and send and receive data streams encrypted via a secure data tunnel through a built-in SIM card. The cloud-based authentication management platform is used to receive and verify authentication data reported by the gateway, and to call the operator's platform interface to coordinate tunnel authorization and permission management. Operator network infrastructure, including the radio access network and core network that provide mobile access, as well as the SIM card management and policy control platform responsible for SIM card lifecycle management, policy control and secure tunnel establishment; Enterprise intranet boundary security devices are configured to interface with the secure tunnel endpoints of the operator's network infrastructure, and are responsible for the final decryption, access control and auditing of inbound and outbound tunnel traffic based on dynamic permissions.
Citation Information
Cited By
An instruction security reinforcement system and verification method for intelligent unmanned equipment
CN122160201A